<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T16:42:50.954261+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-317417</id>
    <title>EUVD-2026-317417</title>
    <updated>2026-10-08T16:42:51.000774+00:00</updated>
    <content>EUVD-2026-317417</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-317417"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-42350</id>
    <title>fkie_cve-2026-42350</title>
    <updated>2026-10-08T16:42:51.000814+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Kargo is vulnerable to open redirect in UI OIDC login flow via the redirectTo query parameter. This issue has been patched in versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-42350"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g7gw-m874-7rmf</id>
    <title>GHSA-g7gw-m874-7rmf — Kargo has Open Redirect in UI OIDC Login Flow via redirectTo Query Parameter</title>
    <updated>2026-10-08T16:42:51.000848+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/akuity/kargo</p>
<p>## Summary</p>
<p>The Kargo UI reads a `redirectTo` query parameter on the `/login` and `/token-renew` routes and, following a successful OIDC authentication, uses its value as the destination for client-side navigation. The parameter is treated as a path string but is not constrained to targets within the UI's own origin. Protocol-relative values (e.g. `//attacker.example.com`) and values using a backslash prefix (e.g. `/\attacker.example.com`) are accepted and result in navigation to an external origin.</p>
<p>An attacker can exploit this by crafting a URL of the form `https://kargo.example.com/login?redirectTo=/token-renew?redirectTo=/\attacker.example.com` and delivering it to a victim through any channel that permits link sharing. When the victim follows the link and signs in to Kargo, the browser is redirected to the attacker-controlled origin. Because the initial URL resolves to the legitimate Kargo host and the user is genuinely authenticated in the process, the redirect inherits the perceived trust of the user's own Kargo instance.</p>
<p>The principal risk is that such a redirect can serve as a stepping stone for credentials phishing. The attacker-controlled page can present a UI resembling Kargo or an associated identity provider and solicit credentials from the user. The vulnerability does not, by itself, expose any data from Kargo or permit modification of Kargo resources, and it does not affect authentication when Kargo's built-in admin credentials are used.</p>
<p>## Base Metrics</p>
<p>Th…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g7gw-m874-7rmf"/>
  </entry>
</feed>
